Overview
This Privacy Policy explains how Ironarb Capital (“we”, “us”) collects, uses, stores, discloses, and protects personal data when you visit our website, create and use an account on the Platform, contact support, or apply for and use any services we offer.
“Personal data” means any information relating to an identified or identifiable individual. This Policy is intended to meet transparency requirements under applicable data protection and privacy law.
This Policy applies whether you are a visitor, an account holder, a subscriber, or a prospective client. If you provide personal data about another person, you confirm you are authorised to do so and to allow us to use it as described here. If you do not agree with this Policy, you should not use the Platform or submit personal data to us. If you have any questions, please contact us.
Roles & scope
Ironarb Capital is the data controller for the personal data described in this Policy. We use service providers (data processors) to support our operations, such as hosting, security, analytics, communications, payment processing, and customer support tooling. We require them to process personal data only on our instructions and to maintain appropriate security.
Where you apply for or use trading or other regulated services, additional processing may be required, including identity verification and financial-crime controls. Those activities are also covered by this Policy unless a product-specific notice states otherwise.
Personal data we collect
We collect personal data in the categories below. What we collect depends on how you use our services.
Data you provide to us
- account and profile data, such as name where provided, username, email address, password (stored as a secure hash), and account settings and preferences;
- subscription selections, entitlements, and marketing or communication preferences;
- billing details and a record of payment status, invoices, and renewals (we generally do not store full payment card numbers, which are typically handled by our payment processors);
- support messages, correspondence, and any files or information you choose to provide when contacting us;
- where you apply for trading or other regulated services, identity and verification information, and financial or suitability information required by applicable rules.
Data we collect automatically
- device and usage data, such as IP address, device identifiers where available, device type, operating system, browser type, and language settings;
- activity data, such as pages visited, features used, timestamps, interactions, and error logs, and approximate location derived from IP address;
- cookie identifiers and related information, as described in the Cookies section below.
Data we receive from third parties
- payment confirmations and related identifiers from payment processors;
- verification results and risk or screening indicators from identity verification and screening providers, where applicable;
- aggregated usage metrics, fraud signals, and performance diagnostics from analytics and security providers;
- limited profile identifiers from social login providers, if you choose to use them;
- screening indicators from public and compliance datasets, where applicable.
How we use data & lawful bases
We process personal data only where we have a permitted basis under applicable privacy law. The main purposes and bases are set out below.
- Providing and operating the Platform. To create and administer your account, deliver the services and features you access, provide customer support, and send service communications such as confirmations, security notices, and renewal reminders. Lawful basis: performance of a contract, and steps taken at your request before entering into a contract.
- Payments, accounting, and administration. To process payments, manage billing, maintain accounting records and audit trails, and handle disputes. Lawful basis: contract, legal obligations, and our legitimate interests in administration and business continuity.
- Onboarding and regulated services. Where you apply for or use trading or other regulated services, to carry out identity verification, eligibility assessments where required, account administration, recordkeeping, and compliance monitoring. Lawful basis: contract and legal obligations.
- Security and fraud prevention. To protect accounts, detect and prevent fraud, abuse, and cyber incidents, investigate suspicious activity, and enforce our terms. Lawful basis: our legitimate interests in security and risk management, and legal obligations where applicable.
- Improving our services. To analyse how the Platform is used, diagnose issues, and develop new features. Lawful basis: our legitimate interests in service improvement, and consent where required for certain analytics technologies.
- Marketing. To send product updates and marketing communications where permitted, and to tailor them to your preferences. Lawful basis: our legitimate interests in direct marketing and consent where required.
- Legal and regulatory matters. To comply with legal process and requests from authorities, establish or defend legal claims, and manage complaints. Lawful basis: legal obligations and our legitimate interests in legal protection.
Marketing & opt-out
You can opt out of marketing communications at any time by using the unsubscribe option in the message or by contacting us through our contact page.
We may still send non-marketing communications that are necessary to provide the service, such as security notices, billing messages, changes to terms, or important operational notifications.
Support chat & file uploads
When you contact support, you should not upload malware or harmful code, personal data of third parties unless you are authorised and it is necessary for support, or sensitive information unless it is strictly necessary and you have a lawful basis to share it.
Support messages and files may be stored in our support systems, accessed by authorised staff and contractors, and used to resolve issues, improve support quality, and maintain audit trails. We may automatically scan uploads for security threats and may block, quarantine, or delete content that presents a risk or breaches our terms.
International transfers
Your personal data may be processed in locations other than your own, for example where our service providers or their sub-processors operate.
Where we transfer personal data across borders, we implement lawful safeguards as required. These may include contractual safeguards and operational controls consistent with applicable cross-border disclosure requirements, transfers to locations recognised as providing adequate protection where applicable, and additional technical and organisational measures where appropriate. You may contact us to request further information about our transfer safeguards.
Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy, including to meet legal, regulatory, accounting, and security requirements. Retention periods vary by context: account and support data are generally kept for the life of the relationship and a reasonable period afterwards; billing and finance records are kept as required by applicable law; onboarding, verification, and trading records are kept for the periods required under applicable recordkeeping and financial-crime obligations, which may extend beyond the end of the relationship; and security logs are kept for a reasonable period based on risk and operational needs.
We may retain and use data in anonymised or aggregated form, where it no longer identifies you, for analytics and service improvement.
Automated decision-making & profiling
We may use automated tools to support fraud and abuse detection, security risk scoring, operational monitoring such as detecting unusual logins, and compliance screening during onboarding where applicable.
Where a decision producing legal or similarly significant effects is made solely by automated means, we will provide appropriate information and, where required, enable you to request human review, express your point of view, and contest the decision, in accordance with applicable privacy law.
Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These may include access controls, encryption in transit, secure credential handling, monitoring, staff training, and least-privilege access.
No system is completely secure. You are responsible for keeping your credentials confidential and for securing the devices you use to access the Platform.
Your privacy rights
Subject to applicable conditions and exemptions, you may have the right to:
- access your personal data;
- rectify inaccurate or incomplete personal data;
- erase personal data, where applicable;
- restrict processing;
- object to processing, including direct marketing and certain processing based on legitimate interests;
- request portability of data, where processing is based on contract or consent and carried out by automated means;
- withdraw consent at any time where we rely on consent, without affecting prior lawful processing.
To exercise these rights, please contact us. We may need to verify your identity before responding.
Complaints
If you have concerns about our privacy practices, please contact us first and we will seek to resolve the issue. You may also lodge a complaint with the competent data protection authority.
Children
Our website and the Platform are not directed to children and are intended for individuals who meet the minimum age required under applicable law. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps.
Changes to this policy
We may update this Privacy Policy from time to time. The current version will be posted on our website and the Platform and will apply from the stated effective date. Where required, we will provide additional notice of material changes.
